Scenario library / Supply chain
Managed File Transfer Platform Breach: a tabletop exercise scenario
A vendor discloses that a zero-day in its file transfer product was exploited across its customer base. Your organisation used it to move payroll and client reporting files.
75–90 min · Executive + vendor management + legal

What this is modelled on
Modelled on mass-exploitation events against internet-facing file transfer products, where a single vulnerability lets an actor pull data from hundreds of organisations before any patch exists, and victims learn of it through the vendor or the actor's leak site.
Why it matters
You cannot patch your way out of an event that already happened. The work is scoping data you did not send yourself, coordinating with a vendor under strain, and handling notification duties for data belonging to other people.
Exercise objectives
- Establish what data traversed the platform and for whom
- Test third-party incident escalation and contractual leverage
- Rehearse notification decisions where you are a processor, not just a controller
- Assess concentration risk across other vendors
Decision points tested
- Assume-compromise posture versus wait for forensic confirmation
- What you tell clients before scoping completes
- Whether to suspend the platform and how work continues
- Regulatory clocks and who starts them
Sample inject timeline
- T+0
Vendor advisory
The vendor confirms active exploitation and asks all customers to assume compromise.
- T+20
Log gaps
The platform retained only seven days of transfer logs; the exploitation window is longer.
- T+40
Client contact
Two enterprise clients demand written confirmation of whether their data was involved, within 24 hours.
- T+60
Leak site listing
The actor posts a victim list that includes your organisation, with a sample file.
What the after-action report should capture
- Data inventory accuracy for third-party platforms
- Log retention shortfalls
- Contractual notification terms actually invoked
- Vendor concentration findings
Run this scenario with your team
Tailor it to your environment with AI, run the injects live, and export a web or PDF after-action report when the exercise ends.
